Platform

Evidence is produced with the action—not reconstructed afterward

Decision → execution authority → consumption → dispatch → outcome → verification on declared governed paths, with evidence state and coverage stated on this page.

Proof chain

  1. Identity and actor chain
  2. Mission, authority derivation, and approval
  3. Policy decision and policy version
  4. Execution-authority record and consumption
  5. Dispatch, external result, and reconciliation

Certifications and recognition

SOC 2 ISO 27001 AuthZEN KuppingerCole Identity Fabrics Leader

EmpowerID is recognized in KuppingerCole Leadership Compass Identity Fabrics. See analyst research for details.

Control continuum — where architectures stop →

What we prove, where we prove it

Claims are scoped to declared enforcement paths. Cells describe evidence state — not product release stage or a ranking.

Proof claimMCP gatewayLLM gatewayWorkflow / connectorCredential mediationContainment
Suspended or revoked authority blocks the next consequential action on the declared path.Partially evidencedNot applicableNot applicableNot applicablePartially evidenced
A material parameter change invalidates the prior decision or permit.Partially evidencedNot applicablePartially evidencedNot applicableNot applicable
Only one successful consumption occurs per permit.Not applicableNot applicableNot applicableNot applicableNot applicable
One durable dispatch-intent record is created per successful consumption.Not applicableNot applicableNot applicableNot applicableNot applicable
Reusable credentials do not enter agent or model context on the declared governed route.Not applicableNot applicableNot applicablePartially evidencedNot applicable
Denial occurs before credential release and target dispatch.Partially evidencedPartially evidencedNot applicableNot applicableNot applicable

Proof claim detail

Suspended or revoked authority blocks the next consequential action on the declared path.

Evidence state
Shown or tested on named paths or configurations; behavior elsewhere is not claimed.
Partially evidenced
Evidence basis
Named demonstration — Shown end to end in a specific, repeatable demonstration on a declared path.
Depends on
containmentmcp-gateway-enforcement
How to check it
Withdraw authority; attempt next action; measure deny before external contact.
Scope
Runs that return through a governed enforcement point. Limitation: Does not reverse completed external effects.

Awaiting capability-owner confirmation. Not yet presented as proof.

A material parameter change invalidates the prior decision or permit.

Evidence state
Shown or tested on named paths or configurations; behavior elsewhere is not claimed.
Partially evidenced
Evidence basis
Named demonstration — Shown end to end in a specific, repeatable demonstration on a declared path.
Depends on
mcp-gateway-enforcementworkflow-connector-execution
How to check it
Mutate material argument; re-evaluate at PEP.
Scope
Actions where arguments are bound to approval. Limitation: Materiality rules are policy-defined.

Awaiting capability-owner confirmation. Not yet presented as proof.

Only one successful consumption occurs per permit.

Evidence state
Claim is scoped and reviewable, but public test evidence or owner confirmation is outstanding.
Not yet evidenced
Evidence basis
Architecture only — Design intent. No implementation is claimed.
Depends on
permit-consumption
How to check it
Attempt second consumption from same permit.
Scope
Governed execution boundary. Limitation: Does not claim one network attempt or one external effect. Concurrency, recovery, replay, expiration, and storage failure require explicit test conditions.

Awaiting capability-owner confirmation. Not yet presented as proof.

One durable dispatch-intent record is created per successful consumption.

Evidence state
Claim is scoped and reviewable, but public test evidence or owner confirmation is outstanding.
Not yet evidenced
Evidence basis
Architecture only — Design intent. No implementation is claimed.
Depends on
permit-consumption
How to check it
Inspect dispatch ledger after consumption.
Scope
Governed execution boundary. Limitation: Transport may retry; outcome verified independently.

Awaiting capability-owner confirmation. Not yet presented as proof.

Reusable credentials do not enter agent or model context on the declared governed route.

Evidence state
Shown or tested on named paths or configurations; behavior elsewhere is not claimed.
Partially evidenced
Evidence basis
Named demonstration — Shown end to end in a specific, repeatable demonstration on a declared path.
Depends on
credential-acquisition-injection
How to check it
Inspect agent and model context across full run.
Scope
Declared governed routes and controlled ingress paths. Limitation: Credentials already held from other sources excluded.

Awaiting capability-owner confirmation. Not yet presented as proof.

Denial occurs before credential release and target dispatch.

Evidence state
Shown or tested on named paths or configurations; behavior elsewhere is not claimed.
Partially evidenced
Evidence basis
Named demonstration — Shown end to end in a specific, repeatable demonstration on a declared path.
Depends on
mcp-gateway-enforcementllm-gateway-enforcement
How to check it
Deny action; verify no credential release and no target change.
Scope
Governed PEP paths. Limitation: Paths that bypass PEP not covered.

Awaiting capability-owner confirmation. Not yet presented as proof.

Target state is verified where independent read-back exists.

Evidence state
Shown or tested on named paths or configurations; behavior elsewhere is not claimed.
Partially evidenced
Evidence basis
Named demonstration — Shown end to end in a specific, repeatable demonstration on a declared path.
Depends on
workflow-connector-execution
How to check it
Compare execution response to independent read-back.
Scope
Targets reachable through connectors with post-state read. Limitation: Otherwise marked uncertain or reconciliation required.

Awaiting capability-owner confirmation. Not yet presented as proof.

Authority, decision, dispatch, and observed outcome are linked in the evidence chain.

Evidence state
Shown or tested on named paths or configurations; behavior elsewhere is not claimed.
Partially evidenced
Evidence basis
Named demonstration — Shown end to end in a specific, repeatable demonstration on a declared path.
Depends on
mcp-gateway-enforcementworkflow-connector-execution
How to check it
Replay evidence chain for audit.
Scope
Configured governed paths with evidence export. Limitation: Coverage varies by path and connector.

Awaiting capability-owner confirmation. Not yet presented as proof.

Governed, issuance-gated, observed-only, and unmanaged paths are documented.

Evidence state
Claim is scoped and reviewable, but public test evidence or owner confirmation is outstanding.
Not yet evidenced
Evidence basis
Architecture only — Design intent. No implementation is claimed.
How to check it
Compare declared paths to bypass analysis.
Scope
Customer deployment scope matrix. Limitation: Customer-specific gaps require assessment.

Awaiting capability-owner confirmation. Not yet presented as proof.

One proof run

Required proof design — authority suspension path

One illustrative run: authority is active for a bounded piece of work, an action is proposed at the enforcement point, authority is then suspended, and the next action is re-evaluated and denied. No credential is released, nothing reaches the target, and the denial itself is recorded as evidence.

  1. 1

    Authority active for bounded work

    Illustrative sequence for review.

    Permitted
  2. 2

    Action proposed at MCP PEP

    Illustrative sequence for review.

    Permitted
  3. 3

    Authority suspended

    Illustrative sequence for review.

    Permitted
  4. 4

    Next action evaluated

    Illustrative sequence for review.

    Held for assurance
  5. 5

    Denied — no credential release

    Credential mediator does not release on deny.

    Denied
  6. 6

    No target dispatch

    Illustrative sequence for review.

    Denied
  7. 7

    Evidence recorded

    Illustrative sequence for review.

    Denied

Performance and failure behavior

PropertyMeasurement boundaryResult
Revoke-to-deny latencyNext MCP turn after authority withdrawalNot yet published
Policy evaluation at PEPDeclared MCP routeNot yet published
Failure on verification timeoutConnector read-back unavailableReconciliation required — not success

Technical diligence brief

Scope matrix, threat model, bypass analysis, test cases, and known limitations for declared governed paths.

Full measured results and release references are provided under NDA. Public summary on this page.

Download public evaluation brief
Get Started

Connect once. Govern consistently. Change safely.

EmpowerID Identity Fabric — governance, authorization, and execution for people, NHIs, and AI agents.

Request Demo See the platform in action
Talk to an Expert Technical consultation
EmpowerID AI

EmpowerID AI Assistant

Online

EmpowerID AI
EmpowerID AI
Hello! How can I help you today?
05:10 PM

Suggested questions:

Powered by EmpowerID AI